T09 · Insecure Skill Coding Practices
- Location
scripts/analyze_family.py:337- Finding
Stored HTML and JavaScript Injection in Generated Patent Reports
- Content
View full analysis
{{ const fill = n.depth === 0 ? "#1a73e8" : (n.depth === 1 ? "#34a853" : "#fbbc04"); const textColor = n.depth <= 1 ? "white" : "#202124"; svgContent += ` ${{n.label}} ${{n.country || ""}} ${{n.date || ""}} `; }}); svg.innerHTML = svgContent; ``` Other input fields are directly interpolated into HTML attributes and element bodies: ```python items.append(f'''🔗 {p.get("pn","")}
``` The attacker-controlled data source is loaded without validation: ```python with open(args.data_json, "r", encoding="utf-8") as f: data = json.load(f) html = build_html(data) ``` ### Technical Analysis The report generator treats values loaded from the input JSON as trusted markup. P ...[truncated 2698 chars]- Remediation
View remediation
... ``` Before embedding, encode `<` as `\u003c` so that `` cannot terminate the element. Parse the content using `JSON.parse(document.getElementById("tree-data").textContent)`. 6. Validate the loaded JSON against a strict schema: - Enforce expected scalar types. - Limit string lengths and collection sizes. - Reject unexpected properties where practical. - Validate dates, patent numbers, legal-status values, and URLs. 7. Add a restrictive Content Security Policy to the generated report. Prefer external or nonce-based scripts and prohibit inline script execution. This should be defense in depth rather than a replacement for output encoding. 8. Add automated tests using payloads in every rendered field, including HTML tags, quote characters, template-literal delimiters, ``, SVG event handlers, and dangerous URL schemes. ]]>
